Do not allow deactivated auth to pass mongooseim checks

This commit is contained in:
Hannah Ward 2020-04-27 17:03:07 +01:00
parent 01cc93b687
commit fd04237ad8
2 changed files with 22 additions and 1 deletions

View file

@ -27,7 +27,7 @@ defmodule Pleroma.Web.MongooseIM.MongooseIMController do
def check_password(conn, %{"user" => username, "pass" => password}) do
with %User{password_hash: password_hash} <-
Repo.get_by(User, nickname: username, local: true),
Repo.get_by(User, nickname: username, local: true, deactivated: false),
true <- Pbkdf2.checkpw(password, password_hash) do
conn
|> json(true)

View file

@ -9,6 +9,7 @@ defmodule Pleroma.Web.MongooseIMController do
test "/user_exists", %{conn: conn} do
_user = insert(:user, nickname: "lain")
_remote_user = insert(:user, nickname: "alice", local: false)
_deactivated_user = insert(:user, nickname: "meanie", deactivated: true)
res =
conn
@ -30,11 +31,21 @@ defmodule Pleroma.Web.MongooseIMController do
|> json_response(404)
assert res == false
res =
conn
|> get(mongoose_im_path(conn, :user_exists), user: "meanie")
|> json_response(404)
assert res == false
end
test "/check_password", %{conn: conn} do
user = insert(:user, password_hash: Comeonin.Pbkdf2.hashpwsalt("cool"))
deactivated_user =
insert(:user, password_hash: Comeonin.Pbkdf2.hashpwsalt("cool"), deactivated: true)
res =
conn
|> get(mongoose_im_path(conn, :check_password), user: user.nickname, pass: "cool")
@ -55,5 +66,15 @@ defmodule Pleroma.Web.MongooseIMController do
|> json_response(404)
assert res == false
res =
conn
|> get(mongoose_im_path(conn, :check_password),
user: deactivated_user.nickname,
pass: "cool"
)
|> json_response(404)
assert res == false
end
end